VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

814 CVEsRSS

CVE-2026-83175Medium· 6.5
1w ago

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core)

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with n…

▾ SunlitOracle Corporation · Oracle Application Object LibraryEPSS 0.37%via NVD
CVE-2026-83167High· 7.5
1w ago

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core)

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ TwilightOracle Corporation · Oracle Application Object LibraryEPSS 0.42%via NVD
CVE-2026-83116High· 7.7
1w ago

Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools)

Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attac…

▾ TwilightOracle Corporation · Oracle Order ManagementEPSS 0.37%via NVD
CVE-2026-76672Critical· 9.9
1w ago

A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information

A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially cr…

▾ Midnightarubanetworks · edgeconnect_sd-wan_orchestratorEPSS 0.53%via NVD
CVE-2026-76692High· 7.1
1w ago

A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain limited information from memory and disrupt the normal operation of the affected service

A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain limited information from memory and disrupt the normal operation of the affected service. Successful exploitation co…

▾ TwilightHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.28%via NVD
CVE-2026-76697Medium· 6.5
1w ago

A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote attacker authenticated with low privileges to access sensitive information

A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker …

▾ SunlitHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.45%via NVD
CVE-2026-76706Medium· 5.3
1w ago

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could result in the disclosure of security-rele…

▾ Sunlitarubanetworks · edgeconnect_sd-wan_orchestratorEPSS 0.42%via NVD
CVE-2026-76707Medium· 4.3
1w ago

A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents

A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents. Successful exploitation could allow an attacker to gain insight into internal services an…

▾ SunlitHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.23%via NVD
CVE-2026-69212Medium· 5.9PoC
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The FollowRedirect client middleware strips Authorization and Cookie headers only when a redirect changes authority, but authority comparison excludes the URI…

▾ Twilighthttp4s · http4sEPSS 0.28%via NVD
CVE-2026-0197Medium· 4.4
1w ago

In VPU, there is a possible information dislclosure due to a logic error in the code

In VPU, there is a possible information dislclosure due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-56882High· 8.8
1w ago

In Cellular Modem, there is a possible information disclosure due to a logic error in the code

In Cellular Modem, there is a possible information disclosure due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Twilightgoogle · androidEPSS 0.39%via NVD
CVE-2026-91965High· 7.5PoC
1w ago

WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints

WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream…

▾ MidnightWWBN · AVideoEPSS 0.45%via NVD
CVE-2026-91980Medium· 4.3PoC
1w ago

vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members

vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members. Attackers can attach arbitrary team IDs via the project teams endpoint to retrieve comp…

▾ Twilightgo-vikunja · vikunjaEPSS 0.31%via NVD
CVE-2026-91981Medium· 4.3PoC
1w ago

Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints

Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers with a read-only share link can enumerate project users via the projects endpoint and confirm arbitrary usernames ex…

▾ Twilightgo-vikunja · vikunjaEPSS 0.31%via NVD
CVE-2026-91985High· 7.5PoC
1w ago

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-…

▾ Midnightgo-vikunja · vikunjaEPSS 0.43%via NVD
CVE-2026-91992Medium· 5.9PoC
1w ago

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through th…

▾ Twilighttornadoweb · tornadoEPSS 0.26%via NVD
CVE-2026-87792High· 8.7
1w ago

The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" conte…

The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" conte…

▾ TwilightDevelopers Italia · design-scuole-wordpress-themeEPSS 0.46%via NVD
CVE-2026-92031Medium· 6.5
1w ago

Information disclosure in the Graphics: ImageLib component

Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

▾ SunlitMozilla · FirefoxEPSS 0.33%via NVD
CVE-2026-92044High· 7.5
1w ago

Information disclosure in the Networking: HTTP component

Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.47%via NVD
CVE-2026-92070Medium· 4.3
1w ago

Information disclosure in the Networking component

Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ SunlitMozilla · FirefoxEPSS 0.34%via NVD
CVE-2026-18232Medium· 5.3
1w ago

The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved …

The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved …

▾ SunlitEPSS 0.21%via NVD
CVE-2026-16592Low· 2.7
1w ago

The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as low as Contributor to disclose non-public listing content, including password-…

The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as low as Contributor to disclose non-public listing content, including password-…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-15758Medium· 5.3
1w ago

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter. This makes it possible…

▾ Sunlitiberezansky · 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image GalleryEPSS 0.27%via NVD
CVE-2026-90881Medium· 5.3PoC
1w ago

A weakness has been identified in D-Link DIR-882 up to 20260814

A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The attack may be launc…

▾ TwilightD-Link · DIR-882EPSS 0.83%via NVD
CVE-2026-54689Medium· 6.3PoC
1w ago

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL policy in src/url-reader.ts can be bypassed while MCP_HTTP_HARDEN is en…

▾ Twilightihor-sokoliuk · mcp-searxngEPSS 0.19%via NVD
CVE-2026-55178High· 7.5
1w ago

GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder

GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.2.3, multiple read and link endpoints authorize only the resource named in the request URL and fail to re-authorize a…

▾ Twilightgeolens-io · geolensEPSS 0.65%via NVD
CVE-2026-54254Medium· 5.9
1w ago

Cyberdrop-DL is a bulk asynchronous downloader for multiple file hosts

Cyberdrop-DL is a bulk asynchronous downloader for multiple file hosts. From 8.5.0 until 9.14.0, the Pixeldrain crawler uses substring host matching instead of requiring the input host to be an exact member of SUPPORTED_DOMAINS, and then…

▾ SunlitCyberdrop-DL · cyberdrop-dlEPSS 0.53%via NVD
CVE-2026-49254Low· 2.9
1w ago

Dragonfly is an open source P2P-based file distribution and image acceleration system

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4, manager/router/router.go registers GET /api/v1/oauth and GET /api/v1/oauth/:id without jwt.MiddlewareFunc() or RBAC(), while manager/h…

▾ Sunlitdragonflyoss · dragonflyEPSS 0.48%via NVD
CVE-2026-45048High· 8.5
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticated user queries s…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.43%via NVD
CVE-2026-84576Medium· 5.5
1w ago

This issue was addressed with improved checks

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

▾ Sunlitapple · macosEPSS 0.16%via NVD
CWE-200 vulnerabilities (CVEs) — page 7 · VulnSea